Rule: Email heuristics
Rule key: email_heuristics · Default weight: 0.85 · Tier: Lite
Combines three sub-signals on the billing email address. Scores stack up to the per-rule cap of 100.
1. Disposable domain (70 points)
The plugin bundles 153 known disposable-email domains (Mailinator, Guerrilla Mail, 10MinuteMail, YOPmail, etc.). Match is exact-domain — sub-domains aren\’t automatically blocked. Add your own under Settings → Disposable Email.
2. Prior chargeback on the email (60 points)
Looks up the canonicalised email against the wfg_chargebacks table. Requires the chargeback webhook integration to be active and populating that table.
3. Suspicious pattern (25 points)
One or more of:
- Digits-only domain label (e.g.
buyer@1234.com) - Suspicious TLD (
.xyz,.top,.click,.work,.country, …) - Gibberish local-part — Shannon-entropy-based check that flags strings like
qzwxecvbnmk